pki tool shows and builds crlSign keyUsage

This commit is contained in:
Martin Willi
2011-01-05 16:45:56 +01:00
parent 6807c0ca2c
commit bb0cda2fa9
3 changed files with 14 additions and 2 deletions
+5 -1
View File
@@ -120,6 +120,10 @@ static int issue()
{ {
flags |= X509_CLIENT_AUTH; flags |= X509_CLIENT_AUTH;
} }
else if (streq(arg, "crlSign"))
{
flags |= X509_CRL_SIGN;
}
else if (streq(arg, "ocspSigning")) else if (streq(arg, "ocspSigning"))
{ {
flags |= X509_OCSP_SIGNER; flags |= X509_OCSP_SIGNER;
@@ -378,7 +382,7 @@ static void __attribute__ ((constructor))reg()
{"[--in file] [--type pub|pkcs10] --cakey file | --cakeyid hex", {"[--in file] [--type pub|pkcs10] --cakey file | --cakeyid hex",
" --cacert file --dn subject-dn [--san subjectAltName]+", " --cacert file --dn subject-dn [--san subjectAltName]+",
"[--lifetime days] [--serial hex] [--crl uri]+ [--ocsp uri]+", "[--lifetime days] [--serial hex] [--crl uri]+ [--ocsp uri]+",
"[--ca] [--pathlen len] [--flag serverAuth|clientAuth|ocspSigning]+", "[--ca] [--pathlen len] [--flag serverAuth|clientAuth|crlSign|ocspSigning]+",
"[--digest md5|sha1|sha224|sha256|sha384|sha512] [--outform der|pem]"}, "[--digest md5|sha1|sha224|sha256|sha384|sha512] [--outform der|pem]"},
{ {
{"help", 'h', 0, "show usage information"}, {"help", 'h', 0, "show usage information"},
+4
View File
@@ -105,6 +105,10 @@ static void print_x509(x509_t *x509)
{ {
printf("CA "); printf("CA ");
} }
if (flags & X509_CRL_SIGN)
{
printf("CRLSign ");
}
if (flags & X509_AA) if (flags & X509_AA)
{ {
printf("AA "); printf("AA ");
+5 -1
View File
@@ -113,6 +113,10 @@ static int self()
{ {
flags |= X509_CLIENT_AUTH; flags |= X509_CLIENT_AUTH;
} }
else if (streq(arg, "crlSign"))
{
flags |= X509_CRL_SIGN;
}
else if (streq(arg, "ocspSigning")) else if (streq(arg, "ocspSigning"))
{ {
flags |= X509_OCSP_SIGNER; flags |= X509_OCSP_SIGNER;
@@ -257,7 +261,7 @@ static void __attribute__ ((constructor))reg()
{"[--in file | --keyid hex] [--type rsa|ecdsa]", {"[--in file | --keyid hex] [--type rsa|ecdsa]",
" --dn distinguished-name [--san subjectAltName]+", " --dn distinguished-name [--san subjectAltName]+",
"[--lifetime days] [--serial hex] [--ca] [--ocsp uri]+", "[--lifetime days] [--serial hex] [--ca] [--ocsp uri]+",
"[--flag serverAuth|clientAuth|ocspSigning]+", "[--flag serverAuth|clientAuth|crlSign|ocspSigning]+",
"[--digest md5|sha1|sha224|sha256|sha384|sha512] [--outform der|pem]"}, "[--digest md5|sha1|sha224|sha256|sha384|sha512] [--outform der|pem]"},
{ {
{"help", 'h', 0, "show usage information"}, {"help", 'h', 0, "show usage information"},